Unauthorized Session Management in FreeSWITCH via mod_verto
CVE-2026-49843

5.3MEDIUM

Key Information:

Vendor

Signalwire

Vendor
CVE Published:
9 June 2026

What is CVE-2026-49843?

The FreeSWITCH platform, known for its powerful telecom stack, contains a vulnerability in the mod_verto module which improperly manages session identifiers (sessid) during initial connection setup. An unauthenticated network attacker with knowledge of a specific session UUID can exploit this flaw to forcibly terminate an active session. By interfering with the connection establishment, the attacker can evict legitimate clients, resulting in unauthorized access and possible call disruption. This loophole has been addressed in version 1.11.1, which includes patches to enhance session authentication and security measures.

Affected Version(s)

freeswitch < 1.11.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.